UAT-4356 is a state-linked cyberespionage threat actor focused on compromising network perimeter infrastructure, especially Cisco security appliances. The group is closely associated with the ArcaneDoor campaign and is also tracked by Microsoft as Storm-1849. Reporting has linked the actor to a China-nexus ecosystem, although some vendors have described it more cautiously as government-backed without public formal state attribution. UAT-4356 has repeatedly targeted Cisco ASA, Firepower, and Secure Firewall devices, including Firepower eXtensible Operating System environments, by exploiting vulnerabilities in internet-facing VPN and management surfaces. In ArcaneDoor, the actor compromised Cisco ASA devices via zero-day vulnerabilities. In later activity, the group continued operations by exploiting known Cisco ASA and FTD vulnerabilities, including CVE-2025-20333 and CVE-2025-20362, to obtain unauthorized access and deploy custom implants. The actor’s tooling includes LINE VIPER and the FIRESTARTER backdoor. LINE VIPER has been used for post-exploitation functions including VPN authentication bypass, packet capture, credential and key material access, command execution, and suppression of logging. FIRESTARTER is a device-native Linux backdoor designed for Cisco firewall platforms that hooks the LINA process, replaces legitimate WebVPN request-handling logic, and executes attacker-supplied shellcode directly in memory in response to specially crafted authentication-related requests. The malware is notable for stealthy operation inside trusted device processes, minimal on-disk footprint, and persistence mechanisms tied to Cisco Service Platform mount-list manipulation and reboot behavior. It has been observed surviving normal reboots, firmware updates, and patching, enabling the actor to regain access after remediation unless devices are fully reimaged or otherwise thoroughly remediated. Operationally, UAT-4356 emphasizes covert access to edge devices rather than traditional endpoint malware deployment. This provides visibility into VPN, authentication, and network traffic while bypassing many endpoint-focused defenses. Observed behavior includes exploitation for initial access, in-memory payload execution, persistence, post-exploitation on trusted network appliances, and long dwell time in victim environments. Confirmed victimology includes at least a U.S. federal civilian agency, and authorities have assessed the activity may be part of a broader campaign affecting government and critical national infrastructure networks.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
27 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
4 CVEs this actor has used in observed campaigns. 4 of them exploited in the wild.
Die Verwundbarkeiten erhielten die Kennungen CVE-2025-20333 (CVSS: 9.9), CVE-2025-20362 (CVSS: 6.5) und CVE-2025-20363 (CVSS: 9.0). Mit den Advisories gab Cisco auch bekannt, dass die ersten beiden Schwachstellen bereits ausgenutzt werden ... Cisco Talos zeigt ... dass der Akteur UAT-4356 ... die bereits bekannten Sicherheitslücken CVE-2025-20333 und CVE-2025-20362 genutzt [hat], um unauthorisierten Zugriff ... zu erlangen und die Backdoor FIRESTARTER zu installieren.
Die Verwundbarkeiten erhielten die Kennungen CVE-2025-20333 (CVSS: 9.9), CVE-2025-20362 (CVSS: 6.5) und CVE-2025-20363 (CVSS: 9.0). Mit den Advisories gab Cisco auch bekannt, dass die ersten beiden Schwachstellen bereits ausgenutzt werden ... Cisco Talos zeigt ... dass der Akteur UAT-4356 ... die bereits bekannten Sicherheitslücken CVE-2025-20333 und CVE-2025-20362 genutzt [hat], um unauthorisierten Zugriff ... zu erlangen und die Backdoor FIRESTARTER zu installieren.
Cisco Talos previously attributed this group to the ArcaneDoor campaign in 2024, where they exploited two Cisco ASA zero-day vulnerabilities (CVE-2024–20353, CVE-2024–20359) to deploy malware such as Line Dancer and Line Runner.
Cisco Talos previously attributed this group to the ArcaneDoor campaign in 2024, where they exploited two Cisco ASA zero-day vulnerabilities (CVE-2024–20353, CVE-2024–20359) to deploy malware such as Line Dancer and Line Runner.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
State-linked espionage-oriented activity cluster targeting Cisco Firepower, Secure Firewall, ASA, and FTD edge devices using chained vulnerabilities and custom implants for persistence, re-entry, credential harvesting, packet capture, and stealthy long-term access.
Conducting a targeted cyber-espionage campaign against Cisco network edge devices, deploying the custom FIRESTARTER backdoor on Cisco ASA, Firepower, and Secure Firewall appliances running FXOS to achieve stealthy, memory-resident access and long-term espionage.
Conducting a long-term intrusion campaign against Cisco ASA/FTD perimeter devices using the FIRESTARTER backdoor and LINE VIPER loader, with persistence designed to survive patching and reboots. The activity is linked to the earlier ArcaneDoor campaign and appears focused on intelligence collection via compromised network security appliances.
Espionage-focused activity targeting Cisco Firepower/FXOS perimeter devices by chaining known vulnerabilities to deploy the FIRESTARTER backdoor. The group was previously linked to the ArcaneDoor campaign and is using compromised network appliances for unauthorized remote control and espionage.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.